Privacy Policy

Effective Date: 1 April 2026  |  Last Updated: 1 April 2026

1. Who We Are

This Privacy Policy is published by OTD Business Solutions LLP ("we", "us", "our", "Company"), a limited liability partnership registered in India, acting as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

We operate the following products under separate brands:

This Privacy Policy governs the collection, use, and protection of data through the RecallPilot product. All products share a common backend infrastructure operated by OTD Business Solutions LLP.

Registered Address: #1974B, 15th Cross, 24th Main, Sector-1, HSR Layout, Bengaluru, Bengaluru-560102

Contact: contact@recallpilot.in

2. Data We Collect

2.1 Data You Provide Directly

CategoryExamplesPurpose
Identity dataBusiness name, owner name, phone number, email addressAccount creation, communication
Business detailsClinic/business address, Google Business Profile linkReview automation, location identification

2.2 Data Processed on Your Behalf (Patient/Customer Data)

CategoryExamplesPurpose
Patient/customer contact detailsPatient name, phone numberSending reminders and review requests
Appointment dataAppointment dates, treatment typeRecall scheduling, care instructions
Engagement dataSatisfaction rating, Google review statusReview automation, satisfaction tracking

2.3 Data Generated Through Use

CategoryExamples
Communication logsWhatsApp messages sent/received, delivery status, timestamps
Review request recordsReview request timestamps, review completion status
Recall schedules6-month recall dates, reminder sequences
Satisfaction check resultsPost-visit satisfaction responses, ratings
Consent recordsConsent timestamps, method (explicit YES / implicit engagement)

2.4 Technical Data

We use session cookies only for the admin panel (Django session management). We do not use tracking cookies, advertising cookies, analytics pixels, or any third-party trackers on our platform.

3. Purpose of Processing

RecallPilot

General

4. Legal Basis for Processing

BasisApplication
Consent (DPDP Act s6)We obtain consent via WhatsApp keyword ("YES" to confirm, "STOP" to withdraw). Your first message interaction constitutes implicit consent for the purpose of that interaction.
Contract performanceProcessing necessary to deliver the services you have subscribed to (appointment reminders, review requests, recall reminders).
Legal obligationRetention of business records as required by applicable law.

5. Third-Party Data Sharing

We share data only with the following third parties, strictly for the purposes described:

Third PartyData SharedPurposeLocation
Meta / WhatsApp Business APIPhone numbers, message contentSending and receiving WhatsApp messagesGlobal (Meta infrastructure)
Amazon Web ServicesPatient/customer data, business configurationSecure data storage and application hostingap-south-1 (Mumbai, India)
Google Gemini APIMessage content for AI processingNatural language understanding for patient responsesGoogle Cloud (may be outside India — see Section 10)
RazorpayBusiness name, subscription amountSubscription billing and payment processingIndia
Google Business ProfileReview links only — no data sent TO Google by usDirecting patients/customers to leave Google reviewsN/A (outbound links only)

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

6. Data Retention

Data TypeRetention PeriodLegal Basis
Patient/customer data (name, phone, appointment details)Duration of business relationship + 1 yearPurpose limitation (DPDP Act)
Communication logs (WhatsApp messages)Duration of business relationship + 1 yearPurpose limitation (DPDP Act)
Business account data (owner name, email, phone)Duration of business relationship + 1 yearPurpose limitation (DPDP Act)
Review request and satisfaction recordsDuration of business relationship + 1 yearPurpose limitation (DPDP Act)
Session cookies24 hours (session-based)Technical necessity

After the applicable retention period expires, data is permanently deleted or anonymized (personal identifiers removed).

7. Your Rights Under the DPDP Act

As a Data Principal under the DPDP Act 2023, you have the following rights:

RightDescriptionHow to Exercise
Right to AccessRequest a summary of your personal data we process and the processing activitiesEmail the Grievance Officer
Right to CorrectionRequest correction of inaccurate or incomplete personal dataEmail the Grievance Officer or reply via WhatsApp
Right to ErasureRequest deletion of your personal data, subject to legal retention requirementsEmail the Grievance Officer
Right to Withdraw ConsentWithdraw consent at any time; processing before withdrawal remains validReply STOP on WhatsApp or email the Grievance Officer
Right to NominateNominate another person to exercise your rights in case of death or incapacityEmail the Grievance Officer

8. Security Measures

We implement the following technical and organizational measures to protect your data:

9. Cookies

We use session cookies only for the Django admin panel. These cookies:

We do not use any advertising, analytics, or third-party tracking cookies. No cookie consent banner is required as we only use strictly necessary session cookies.

10. Cross-Border Data Transfers

Disclosure: The following data transfers may involve processing outside India:
ServiceData TransferredDestination
Google Gemini APIMessage content for natural language understanding (patient responses, satisfaction checks)Google Cloud servers (location determined by Google; may be outside India)
Meta / WhatsApp Business APIPhone numbers, message contentMeta global infrastructure

All other data (AWS storage, database) is processed within India (ap-south-1, Mumbai). If the Government of India notifies specific categories of data requiring mandatory localization under the DPDP Act, we will take steps to ensure compliance, including evaluating India-region alternatives for AI processing.

11. Children's Data

Our services are designed for business use — specifically for local businesses such as dental clinics, restaurants, hotels, and salons. We do not directly collect personal data from individuals under the age of 18.

Note on patient records: Patient records managed through RecallPilot may include data relating to children (e.g., paediatric dental appointment reminders). This data is processed on behalf of the clinic or business, which is responsible for obtaining appropriate parental/guardian consent. RecallPilot acts as a Data Processor in these cases, not a Data Fiduciary for the child's data. If you believe we have inadvertently collected data from a minor without appropriate consent, please contact our Grievance Officer immediately.

12. Data Breach Notification

In the event of a personal data breach, we commit to:

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

14. Grievance Officer

In accordance with the DPDP Act 2023, we have appointed a Grievance Officer to address your concerns regarding data processing:

Name: Sanjay Chaturvedi

Email: contact@recallpilot.in

Address: #1974B, 15th Cross, 24th Main, Sector-1, HSR Layout, Bengaluru, Bengaluru-560102

Response time: We will acknowledge your request within 48 hours and provide a substantive response within 30 days.

15. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of India, including but not limited to:

Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Bengaluru, Karnataka, India.